Win32/TrojanClicker.Delf.NRZ [Threat Name] go to Threat

Win32/TrojanClicker.Delf.NRZ [Threat Variant Name]

Category trojan
Size 242688 B
Detection created Nov 23, 2013
Detection database version 9087
Aliases TR/Downloader.Gen (Avira)
Short description

Win32/TrojanClicker.Delf.NRZ is a trojan which tries to promote certain web sites. The file is run-time compressed using ASPack .


The trojan does not create any copies of itself.

Other information

The trojan acquires data and commands from a remote computer or the Internet.

The trojan contains a URL address. The HTTP protocol is used.

The trojan sends HTTP requests to simulate clicks on banner advertisements, to inflate web counter statistics etc.

The trojan hooks the following Windows APIs:

  • connect (ws2_32.dll)
  • DirectSoundCreate (dsound.dll)
  • midiStreamOpen (winmm.dll)
  • waveOutWrite (winmm.dll

